TF-EMC2 Meeting March Florence, Italy

Size: px
Start display at page:

Download "TF-EMC2 Meeting March Florence, Italy"

Transcription

1 TF-EMC2 Meeting March Florence, Italy Introduction Diego opened the meeting and welcomed the participants. SCS updates Guy Guy gave an update on the SCS service. There were some recent changes within GlobalSign (GS) as results of which GlobalSign is not part of Cybertust anymore. TERENA had a phone call with GS management (in February), who confirmed that nothing would change for TERENA until Guy reported on the status on planned tasks: - OCSP implementation is under preparation. There will be 5 servers running for this at SURFnet and CESNET. - HTTP POST interface: GS committed to deliver this feature, but there are some delays compared to what was scheduled. TACAR Updates - Licia Licia reported that the final version of the policy is on-line. No other major things were reported. ECAM - Diego Updates Diego gave an update on ECAM, the steering committee group for both TF-EMC2 and TF-Mobility. ECAM members are the work item leaders for both task-forces, plus representatives of the other relevant organisations, such as AARNET. Internet2 representative has not been appointed yet. The group meets approximately once per month via phone-conferences. ECAM addresses issues related to the middleware developments in the various continents. REFEDS - Mikal Linden Mikael gave an updates on REFEDS. Thanks to Mikael inputs, lots of information is now available on the refeds wiki, which is publicly available (read-only) at: Not all NRENs have provided their contributions, so Mikael invited those missing to update the wiki. Action: Licia to send an to the refeds list to remind the missing federations to fill in the wiki. Campus issues (Torbjorn Wiberg) Torbjon gave an update on issues that arise at campus level. Torbjorn pointed out that some issues go beyond technology and include user management and other business processes. 1

2 Torbjorn also reported that a survey showed that that only of users in Sweden have used a proper AAI. The survey also shows that some campuses prefer to deal with only one preferred vendor. OGF Milan Milan reported on the last OGF held in Raleigh (North Carolina). One of the things of interest for EMC2 community was the workshop on federations that took place, focused on how to integrate Shibboleth with Grids. The link with the programme and the presentations was circulated on the list by Licia. ( During OGF in North Carolina there was also a BoF on level of Assurance. There are some suggestions to introduce (within the IGTF) level of assurances in order to match those introduced by NIST (in US). Monitoring - Miroslav Milinovic (SRCE) Miro presented the plan for a monitoring infrastructure at federation level. The monitoring system should be able to allow for e-2-e users report as well as to identify problems in the infrastructure at a particular point in time. Miro proposed a modular approach: - Step1: The first step should be the collection of available tools. One the things that Miro suggested were to add an extra field on the refeds wiki, to report whether a monitoring system is available. - Step2: Identify the elements to monitor - Step 3: Start building the tools; the first tool could be a weather map. Miro also suggest to use the on the refeds wiki to collect information related to tools like PERFsonar and Internet detective. There was a discussion on the middleware diagnostic in terms on how far and detailed we should go. Diego suggested having something similar to the PerfSonar for middleware. Step2: The wiki should contain more more detailed info on the IdPs that are part of the federations. Action: Licia and Miro to work to have Step 1 completed by the summer. Directory - Victoriano Giralt, University of Malaga Victoriano reported on the developments on SCHAC. He mentioned that the University of Malaga and RedIRIS have been awarded the first honour mention (November 2006), for the implementation of user controlled attribute release policies based on schacuserprivateattribute. The latest SCHAC schema (v1.3) was released in January The adoption of the Schema is progressing. Currently SCHAC is being used by: - 11 IdP in HAKA use SCHAC - Rok Papez reported that SCHAC is being used in Slovenia 2

3 - RedIRIS uses SCHAC internally and recommends the SCHAC usage to the Spanish universities. University of Seville, the University of Basque Country and the University of Malaga use SCHAC in production way. - GEANT IdP will use some schac attributes. Victoriano suggested using an experimental version of SCHAC, with some experimental attributes for testing purposes. The new attribute that were suggested to be added, (mainly to match some requirements coming from GEANT2 project are): - schacprojectmembership - schacprojectspecificrole The proposal to have a SCHAC test release was approved. However there was no consensus on the attributes suggested and therefore it was agreed to discuss which attributes to have on the experimental version on the SCHAC list. Action: Victoriano to coordinate the release of the test version and get consensus on the attributes. Victoriano pointed out that SCHAC document section 4.3 (related to students information) is still empty, but there seems to be sufficient interest to work on this. One of the issues to be address is how an university can distinguish between the local students and the foreign students. His suggestion was to use a sort of federative approach, where the local university gets information about foreign students from the students home organisations. Bob said that has worked at similar issues years ago producing a transcript format. It could be worth looking at this. * edupersonaffiliation (epa) Victoriano reported about the semantic differences in Europe in the usage of this attribute. In order to solve the semantic problem, the following proposals were discussed with the MACE group: - Recommending European institutions not to use epa, but use instead edupersonentitlement - Scope the affiliation, having a edupersonscoopedaffiliation - Using numbers * URN Victoriano said that there were some progresses on the interface to handle URNs, even if slower than expected. It was agreed to use REST (instead than SOAP) as language to implement the interface. The project is available at RedIRIS GForge: DAME Project Sasha Neinert Sasha reported on the status of the DAMe project. The implementation of RADIUS + DIAMETER (NAS-SAML) is being tested. The usage of NAS-SAML gives the possibility of using attributes to perform authorisation (authr). The authentication is done via the standard eduroam infrastructure. 3

4 The authorisation attributes are not handled via the RADIUS servers, but by the user s home organisation. RADIUS is used only as a way to carry attributes. The authorisation is done via NAS-SAML, based on SAML attributes and assertions. The next step of the project is to provide universal single sign-on, meaning allowing for: Authentication for network access, via eduroam / NAS-SAML Fetching edugain signed tokens Bootstrap edugain authentication from the NAS-SAML one No need to re-authenticate Milan expressed his concerns about the deployment of the project after the research phase. SIP AAI - Jan Ruzicka, CESNET Jan gave an overview on how SIP protocol works. One of the main issues in using SIP is how to authenticate the users requests to access the SIP service. The only available and implemented solution at the moment is to use TLS + http digest. Another problem to address is how to identify the authoritative servers that are allowed to proxy the data. It was pointed out that are several aspects to look at when talking about authentication: how to authn the users, how to secure the channel, how to secure the voice etc. Diego suggested the task forces operating on voice and video issues to produce a set of use cases, in order for the TF-EMC2 to discuss the best way to deal with the AAI. The use-cases should be ready before TNC and discussed during the AAI meeting on Sunday 20 May. Action: Licia to coordinate the presentations topics for the AA meeting on Sunday 20 May. International Updates Internet 2 updates Bob Morgan Bob reported on Shib2.0. Its SAML2.0 support is ready for tests. OpenSAML is also ready for tests, but I2 is looking for volunteers. Shibboleth2.0 will provide support for CardSpace as well as openliberty integration. InCommon federation is progressing and there is on-going work to interfederate with US Gov E-Authorisation. Australian MW activities Patty McMillan Patty provided an update on the middleware activities in Australia. Some work is ongoing to establish the Australian Access Federation (AAF), which should be in place by the end of The AAF will be shibboleth based and we also use PKI. The certificates will be granted via the universities to users and not via the federation. 4

5 NRENs Updates SUNET Torbjorn Wiberg Torbjorn reported on SWAMID, the SAML/Shibboleth based Swedish federation. SWAMID also includes eduroam. Digital server certificates are provided via SCS service. Some work led by Roland Hedberg, Leif Johansson is ongoing in the Metadirectory field. RedIRIS - Diego Lopez RedIRIS has reached an agreement to integrate PAPI with SUN IdM products. A PAPI implementation for the SUN JAAS is available at the PAPI web site. The result will be that Sun AM will incorporate PAPI proxy capabilities and that PAPI will incorporate SAML2 support. On the federation side Diego reported that there are currently two main federations in Spain (excluding eduroam): CBIC and SAUWoK. The plan is integrate the two of them. Some test are planned between the CBIC federation and commercial providers (JSTOR and Elsevier). RedIRIS is also testing some diagnostic aggregators to provide white lists. Tools under evaluation are: Comercial: Simplicita: Home made: DESCON II: Diego reported on ARCA ( the RSS tool to aggregate and share multimedia contents. ARCA system is divided into channels. A channel represents a source of multimedia content and each institution is associated with one or more channels. Each channel contains a series of events, retransmissions and/or multimedia contents, called channel items. With this structure each institution is responsible for handling their content. TERENA group PEACHES is evaluating ARCA to handle multimedia material. SWITCH Thomas Thomas gave an overview on the SWITCH federation, started in Currently SWITCH are testing Shibboleth 2.0 and working to support also accounting. The MSDN AA subscription from Microsoft can now be accessed through the federation. JISC Nicole Harris Nicole reported about the developments on the federation in UK. The Shibboleth-based federation in UK was lunched in the fall 2006 and it is progressing very well. Level of Assurance, Virtual Organisation and Identity Management are considered by JISC strategic for the development. 5

6 UNI-C Three years of funding have been allocated to establish a federation. The test federation is in place, but no real IdPs yet. The initial idea was to have a shib based federation, but UNI-C might decide to implement the FEIDE model. CRU-RENATER Shib federation. There are already 23 IdP. They have shibbolised captive portals for Wi- Fi roaming. CRU-PKI, which works to issue both server and end-users certs will terminate at the end of CRU-RENATER joined SCS service since the beginning. They developed a prevalidation web interface, which performs all the expected checks. The interface also provides OpenSSL command to generate PKCS#10 requests. CRU has now issued 765 certificates for 80 organisations in its constituency. Works is ongoing to produce the next version of the directory schema: SUPANN. FEIDE Andreas FEIDE moved from their in house developed federation software to SUN open source solution. Andreas reported UNINETT experience with dealing with a commercial provider. Updates from the publisher community Jane Charlton Jane presented the UK Access Management Federation. Work is ongoing to merge this federation with the UKfederation, the shibboleth-federation for higher education. One of the major concerns raised the by the publisher is related to the legal aspects of the UK federation agreements, in particular those aspect that are different from their current agreement. JISC has been negotiating content license deals with publishers for the whole of UK education. These deals are/will be business drivers for the UK Federation. Persistent Ids - Thomas Thomas raised the issue whether there is a role or an interest from the NRENs in the area of persistent identifiers or DOI. The DOI system assigns persistent names to any entity that is expected to use the Internet. One of the scenarios where persistent IDs could be useful is to handle distribution of material produced by the universities via access grid. Diego said that they have experienced the problem. There are several tools for managing users references, such reference manager. Possible activities and decisions on this topic are left for further discussion. SWITCH Group management tool (GMT) Lukas Lukas presented the GMT tool developed by SWITCH to manage groups and privileges. The tool allows group access to resources. 6

7 Bob pointed out that there is a similar tool, Grouper developed by Internet2. Grouper is designed to meet the needs of larger organisations and to delegate the management. There was lots of interest in the tool. The current back-end is file-system based to reduce the components to install, but a database back-end could easily be used. Trust management in Shibboleth and InCommon (Bob Morgan) Bob reported on trust management issues in Shibboleth and InCommon. Shibboleth trust model works in a way that each Shibboleth resource site trusts each shibboleth origin (home), so each assertion signed by the origin site is trusted by the target site. The trust between the home site and the resource sites is established by mean of digitally signed SAML messages where the target and origin server use X.509 key pairs/certificate. Bob explained the pros and cons in using keys and in using a common CAs to issue certificates. In the future there could be a mix scenario, in which federations still use CAs, but where the peers can offer keys. This implies that the federations should be able to handle both models. VOMS Vincenzo Ciaschini Vincenzo presented the latest developments in VOMS. The access to VOMS is based on the DN of the user, which is extracted from the user certificate. SWITCHslcs & VASH - Thomas Thomas presented the work being undertaken by SWITCH to integrate Shibboleth and Glite, the middleware software developed within EGEE. The work consists of two phases: 1. Phase 1 is focused on short-lived credentials service (SLCS). In this way the AAI infrastructure will be able to issue X.509 certificates. 2. Phase 2, called VASH, VOMS Atttributes from Shibbiloth, is focued on making Shib attributes available to grid resources for authr decision. The attributes will be handled by VOMS He explained that the reason to use VOMS is that VOMS is able to bundle attributes certs into proxy certs that are accepted by the Grid applications. VASH is a browser-based Shibboleth SP. There is one VASH per federation and each VASH is connected to VOMS. Next Meeting The next EMC2 meeting will take place on 4-5 September in Prague. 7

8 Summary of the Actions Action : Licia to send an to the refeds list to remind the missing federations to fill in the wiki. Status: Mail sent to the refeds list. There are only two federations for which the information are still missing. Action : Licia and Miro to collect the monitoring tools already available for the current federations. One the things that Miro suggested were to add an extra field on the refeds wiki to report whether a monitoring system is available. Status: The field was added to wiki during the meeting. Action : Victoriano to coordinate the release of the SCHAC test version and to get consensus on the attributes. Action : Licia to coordinate the presentations topics for the AA meeting on Sunday 20 May. Status done. 8

Victoriano Giralt welcomed the participants on behalf of the University of Malaga. Introduction and ECAM announcement (Diego Lopez)

Victoriano Giralt welcomed the participants on behalf of the University of Malaga. Introduction and ECAM announcement (Diego Lopez) 7 th TF-EMC2 Meeting October 16 17, 2006 Malaga, Spain Welcome Victoriano Giralt welcomed the participants on behalf of the University of Malaga. Introduction and ECAM announcement (Diego Lopez) Diego

More information

Connect. Communicate. Collaborate. GN2 JRA5 update. Jürgen Rauschenbach (DFN), JRA5 team 04/02/08 Marseille. JRA5 Team

Connect. Communicate. Collaborate. GN2 JRA5 update. Jürgen Rauschenbach (DFN), JRA5 team 04/02/08 Marseille. JRA5 Team GN2 JRA5 update Jürgen Rauschenbach (DFN), JRA5 team 04/02/08 Marseille eduroam Working on the eduroam database and a new dissemination look (maps) RadSec release 1.0 Beta is out - reasonable stable and

More information

AA Developers Meeting

AA Developers Meeting AA Developers Meeting Attendees Alan Robiette Ali Odaci Bob Morgan David Chadwick David Orrell Diego Lopez Ingrid Melve Licia Florio Lyn Norris Maarten Koopmans Roland Hedberg Thomas Lenggenhager Ton Verschuren

More information

New trends in Identity Management

New trends in Identity Management New trends in Identity Management Peter Gietz, DAASI International GmbH peter.gietz@daasi.de Track on Research and Education Networking in South East Europe, Yu Info 2007, Kopaionik, Serbia 14 March 2007

More information

Unfortunately it was not possible to have people from GRID, so the scenario described in this reports is not complete.

Unfortunately it was not possible to have people from GRID, so the scenario described in this reports is not complete. AA Workshop Report 26-27 November, 2002 Stockholm, Sweden Programme The first workshop about authentication and authorization infrastructure, foreseen in the Terms of Reference of TF-AACE, was arranged

More information

REFEDS Minutes, 22 April 2012

REFEDS Minutes, 22 April 2012 DOC VERSION:0.1 DATE: 24/04/12 PAGE 1/6 title / reference:refeds-minutes-120422 REFEDS Minutes, 22 April 2012 Licia Florio and Nicole Harris Abstract: Minutes of the REFEDS BOF held in conjunction with

More information

SLCS and VASH Service Interoperability of Shibboleth and glite

SLCS and VASH Service Interoperability of Shibboleth and glite SLCS and VASH Service Interoperability of Shibboleth and glite Christoph Witzig, SWITCH (witzig@switch.ch) www.eu-egee.org NREN Grid Workshop Nov 30th, 2007 - Malaga EGEE and glite are registered trademarks

More information

GN2 JRA5: Roaming and Authorisation

GN2 JRA5: Roaming and Authorisation GN2 JRA5: Roaming and Authorisation Jürgen Rauschenbach, DFN TF-NGN Athens 03/11/05 Introduction JRA5 builds a European Roaming Infrastructure (eduroamng) taking into account existing experience from the

More information

TF-EMC2 Meeting: 3-4 December 2008 Utrecht, the Netherlands Licia Florio. Table of Contents

TF-EMC2 Meeting: 3-4 December 2008 Utrecht, the Netherlands Licia Florio. Table of Contents TF-EMC2 M IN U TES Page 1/9 TITLE / R EFERENCE: V.01 TF-EMC2 Meeting: 3-4 December 2008 Utrecht, the Netherlands Licia Florio Table of Contents 1. Welcome...1 2 TF-ECM2 Work Items presentations...1 2.1

More information

Integrating Federations in the International Grid Trust Fabric

Integrating Federations in the International Grid Trust Fabric Integrating Federations in the International Grid Trust Fabric David Groep Nikhef Dutch national institute for sub-atomic physics Grids, Eduroam, Federations Different terms, same issues How to provide

More information

Goal. TeraGrid. Challenges. Federated Login to TeraGrid

Goal. TeraGrid. Challenges. Federated Login to TeraGrid Goal Federated Login to Jim Basney Terry Fleury Von Welch Enable researchers to use the authentication method of their home organization for access to Researchers don t need to use -specific credentials

More information

AARC Overview. Licia Florio, David Groep. 21 Jan presented by David Groep, Nikhef.

AARC Overview. Licia Florio, David Groep. 21 Jan presented by David Groep, Nikhef. AARC Overview Licia Florio, David Groep 21 Jan 2015 presented by David Groep, Nikhef AARC? Authentication and Authorisation for Research and Collaboration support the collaboration model across institutional

More information

JRA5: Roaming and Authorisation

JRA5: Roaming and Authorisation JRA5: Roaming and Authorisation Jürgen Rauschenbach, DFN-Verein 7 th TF-EMC2 Meeting, Malaga 16 17 October 2006 Introduction JRA5 will build a European Roaming Infrastructure based on eduroam JRA5 will

More information

eduroam und andere Themen in GN2-JRA5

eduroam und andere Themen in GN2-JRA5 eduroam und andere Themen in GN2-JRA5 DFNRoaming Workshop Stuttgart 30 November 2006 Jürgen Rauschenbach, DFN-Verein, jrau@dfn.de Inhalt Das GÉANT2 Projekt JRA5 Visionen Was sind Föderationen? eduroam

More information

GN2 JRA5: Roaming and Authorisation - recent results

GN2 JRA5: Roaming and Authorisation - recent results GN2 JRA5: Roaming and Authorisation - recent results Jürgen Rauschenbach (DFN), Klaas Wierenga (SURFnet), Diego Lopez (RedIRIS), Content Overview Roaming infrastructure AAI Structure and Partners JRA5

More information

EGI-InSPIRE. GridCertLib Shibboleth authentication for X.509 certificates and Grid proxies. Sergio Maffioletti

EGI-InSPIRE. GridCertLib Shibboleth authentication for X.509 certificates and Grid proxies. Sergio Maffioletti EGI-InSPIRE GridCertLib Shibboleth authentication for X.509 certificates and Grid proxies Sergio Maffioletti Grid Computing Competence Centre, University of Zurich http://www.gc3.uzh.ch/

More information

16 th TF-EMC 2 Meeting - Wednesday, 22 nd September 2010 Copenhagen, Denmark. The meeting was hosted by WAYF.dk.

16 th TF-EMC 2 Meeting - Wednesday, 22 nd September 2010 Copenhagen, Denmark. The meeting was hosted by WAYF.dk. Page 1/9 TITLE / REFERENCE Minutes of the 16th TF-EMC 2 Meeting 16 th TF-EMC 2 Meeting - Wednesday, 22 nd September 2010 Copenhagen, Denmark. The meeting was hosted by WAYF.dk. Table of Contents 1. Welcome

More information

Results from the EARNEST Technical Study

Results from the EARNEST Technical Study EARNEST Workshop, Amsterdam, 8 May 2007 Results from the EARNEST Technical Study Licia Florio, TERENA florio@terena.org Agenda Technical study Lower layers preliminary results Middleware preliminary results

More information

The JANET Certificate Service

The JANET Certificate Service The JANET Certificate Service Damien Shaw JANET Technical Administration Group 1 JANET SCS Server Certificate Service January 2006 TERENA sign contract Under a GlobalSign Root Certificate JANET SCS began

More information

AARC. Christos Kanellopoulos AARC Architecture WP Leader GRNET. Authentication and Authorisation for Research and Collaboration

AARC. Christos Kanellopoulos AARC Architecture WP Leader GRNET. Authentication and Authorisation for Research and Collaboration Authentication and Authorisation for Research and Collaboration AARC Christos Kanellopoulos AARC Architecture WP Leader GRNET Open Day Event: Towards the European Open Science Cloud January 20, 2016 AARC

More information

education federation CUC 2005, Dubrovnik High-quality Internet for higher education and research

education federation CUC 2005, Dubrovnik High-quality Internet for higher education and research eduroam: towards a pan-european research and education federation CUC 2005, Dubrovnik Klaas.Wierenga@surfnet.nl Contents Introduction to federations Federations for education Network access: eduroam Application

More information

Extending Services with Federated Identity Management

Extending Services with Federated Identity Management Extending Services with Federated Identity Management Wes Hubert Information Technology Analyst Overview General Concepts Higher Education Federations eduroam InCommon Federation Infrastructure Trust Agreements

More information

Need eduperson SCHAC. eduperson and SCHAC. sending attributes outside your organization. Victoriano Giralt

Need eduperson SCHAC. eduperson and SCHAC. sending attributes outside your organization. Victoriano Giralt and sending attributes outside your organization Central Computing Facility University of Málaga Aθηνα November 6th, 2008 and Sending attributes out the need for a common language Need and Sending attributes

More information

Minutes of the REFEDS Fall Meeting, 5 th September 2012, Utrecht

Minutes of the REFEDS Fall Meeting, 5 th September 2012, Utrecht DOC VERSION: 0.1 DATE 05 SEPTEMBER 2012 PAGE 1/8 06/09/12 TITLE / REFERENCE: REFEDS-20120905 Minutes of the REFEDS Fall Meeting, 5 th September 2012, Utrecht Licia Florio and Nicole Harris Abstract: Table

More information

Federated access to Grid resources

Federated access to Grid resources Federated access to Grid resources http://tinyurl.com/loubf Keith Hazelton (hazelton@wisc.edu) Internet2 Middleware Architecture Comm. for Ed. APAN, Singapore, 19-July-06 Topics http://tinyurl.com/loubf

More information

Federated Identities and Services: the CHAIN-REDS vision

Federated Identities and Services: the CHAIN-REDS vision Co-ordination & Harmonisation of Advanced e-infrastructures for Research and Education Data Sharing Federated Identities and Services: the CHAIN-REDS vision Federico Ruggieri, GARR/INFN Joint CHAIN-REDS/ELCIRA

More information

Internet2 Overview, Services and Activities. Fall 2007 Council Briefings October 7, 2007

Internet2 Overview, Services and Activities. Fall 2007 Council Briefings October 7, 2007 Internet2 Overview, Services and Activities Fall 2007 Council Briefings October 7, 2007 Agenda Building Community - Marianne Smith International Partnerships Heather Boyles Middleware and Security - Renee

More information

Greek Research and Technology Network. Authentication & Authorization Infrastructure. Faidon Liambotis. grnet

Greek Research and Technology Network. Authentication & Authorization Infrastructure. Faidon Liambotis. grnet Greek Research and Technology Network Authentication & Authorization Infrastructure Faidon Liambotis faidon@.gr Networking Research and Education February 22 nd, 2011 1 Who am I? Servers & Services Engineer,

More information

Identity Harmonisation. Nicole Harris REFEDS Coordinator GÉANT.

Identity Harmonisation. Nicole Harris REFEDS Coordinator GÉANT. Identity Harmonisation Nicole Harris REFEDS Coordinator GÉANT http://www.aaiedu.hr/dan2015.html the voice that articulates the mutual needs of research and education identity federations worldwide refeds.org

More information

GÉANT Community Programme

GÉANT Community Programme GÉANT Community Programme Building the community Klaas Wierenga Chief Community Support Officer GÉANT Information day, Tirana, 5 th April 1 Membership Association = very large community to serve GÉANT

More information

GN4-2 SA2 Kick-Off Meeting Amsterdam/NL 30/

GN4-2 SA2 Kick-Off Meeting Amsterdam/NL 30/ GÉANT edupki Serving GÉANT Services GN4-2 SA2 Kick-Off Meeting Amsterdam/NL 30/31.05.2016 Reimer Karlsen-Masur, DFN-CERT Services GmbH Slides & Related Materials @ https://www.edupki.org Outline The 3

More information

The challenges of (non-)openness:

The challenges of (non-)openness: The challenges of (non-)openness: Trust and Identity in Research and Education. DEI 2018, Zagreb, April 2018 Ann Harding, SWITCH/GEANT @hardingar Who am I? Why am I here? Medieval History, Computer Science

More information

AARC Blueprint Architecture

AARC Blueprint Architecture AARC Blueprint Architecture Published Date: 18-04-2017 Revision: 1.0 Work Package: Document Code: Document URL: JRA1 AARC-BPA-2017 https://aarc-project.eu/blueprint-architecture AARC Blueprint Architecture

More information

REFEDS Year End Report 2015

REFEDS Year End Report 2015 DOC VERSION: V1.0 DATE: 5 FEB 2016 PAGE 1/12 title / reference: REFEDS Year End Report 2015 Licia Florio, Nicole Harris Abstract: This report provides an overview of the work carried out by REFEDS during

More information

Federated Authentication for E-Infrastructures

Federated Authentication for E-Infrastructures Federated Authentication for E-Infrastructures A growing challenge for on-line e-infrastructures is to manage an increasing number of user accounts, ensuring that accounts are only used by their intended

More information

The AAF - Supporting Greener Collaboration

The AAF - Supporting Greener Collaboration SPUSC 2008 SOUTH PACIFIC USER SERVICES CONFERENCE The AAF - Supporting Greener Collaboration Stuart Allen MAMS MELCOE Macquarie University sallen@melcoe.mq.edu.au What is the AAF? The Australian Access

More information

A collaboration overview: From TF-VSS to GN2 SA6

A collaboration overview: From TF-VSS to GN2 SA6 A collaboration overview: From TF-VSS to GN2 SA6 András Kovács, NIIF/HUNGARNET GN3 SA3-T4 educonf Workshop, Lisbon 19 October 2010 Introduction a bit of history National VC services: Endpoint deployment:

More information

WP JRA1: Architectures for an integrated and interoperable AAI

WP JRA1: Architectures for an integrated and interoperable AAI Authentication and Authorisation for Research and Collaboration WP JRA1: Architectures for an integrated and interoperable AAI Christos Kanellopoulos Agenda Structure and administrative matters Objectives

More information

Moonshot. Workshop on Federated Identity and (OpenStack) Cloud Services - SWITCH

Moonshot. Workshop on Federated Identity and (OpenStack) Cloud Services - SWITCH Moonshot Workshop on Federated Identity and (OpenStack) Cloud Services - SWITCH 2 ABFAB - Federated access beyond web Why?» You ve heard of eduroam Federated network access» You ve heard of Shibboleth,

More information

Options for Joining edugain. Lukas Hämmerle, SWITCH DARIAH Workshop, Köln 18 October 2013

Options for Joining edugain. Lukas Hämmerle, SWITCH DARIAH Workshop, Köln 18 October 2013 Options for Joining edugain Lukas Hämmerle, SWITCH DARIAH Workshop, Köln 18 October 2013 Outline 1. GE ANT and the Enabling Users task 2. Options to Join edugain 3. Discussion 2 GÉANT (GN3plus) - vital

More information

eduperson & family Ajay Daryanani Middleware Engineer, RedIRIS / Red.es Kopaonik, 13th March 2007

eduperson & family Ajay Daryanani Middleware Engineer, RedIRIS / Red.es Kopaonik, 13th March 2007 eduperson & family Ajay Daryanani (ajay.daryanani@rediris.es) Middleware Engineer, RedIRIS / Red.es Kopaonik, 13th March 2007 1 1 Outline 1. eduperson Background Attributes 2. Extending eduperson Example:

More information

Middleware, Ten Years In: Vapority into Reality into Virtuality

Middleware, Ten Years In: Vapority into Reality into Virtuality Middleware, Ten Years In: Vapority into Reality into Virtuality Dr. Ken Klingenstein, Senior Director, Middleware and Security, Internet2 Technologist, University of Colorado at Boulder Topics Middleware,

More information

Introduction of Identity & Access Management Federation. Motonori Nakamura, NII Japan

Introduction of Identity & Access Management Federation. Motonori Nakamura, NII Japan Introduction of Identity & Access Management Federation Motonori Nakamura, NII Japan } IP networking } The network enables a variety type of attractive applications } Communication E-mail Video conferencing

More information

TF-VVC is not directly related with any of the GN2 JRA s, but in some activity areas the task force is collaborating with the GN2 JRA1 and JRA5.

TF-VVC is not directly related with any of the GN2 JRA s, but in some activity areas the task force is collaborating with the GN2 JRA1 and JRA5. TF-VVC (Voice, Video and Collaboration) http://www.terena.nl/tech/task-forces/tf-vvc/ TF-VVC task force is the successor of TF-Netcast task force, which completed its work in the spring of 2004. TF-Netcast

More information

CILogon. Federating Non-Web Applications: An Update. Terry Fleury

CILogon. Federating Non-Web Applications: An Update. Terry Fleury Federating Non-Web Applications: An Update Terry Fleury tfleury@illinois.edu This material is based upon work supported by the National Science Foundation under grant number 0943633. Any opinions, findings,

More information

Canadian Access Federation: Trust Assertion Document (TAD)

Canadian Access Federation: Trust Assertion Document (TAD) Participant Name: St. Thomas University Canadian Access Federation: Trust Assertion Document (TAD) 1. Purpose A fundamental requirement of Participants in the Canadian Access Federation is that they assert

More information

Report for the GGF 16 BoF for Grid Developers and Deployers Leveraging Shibboleth

Report for the GGF 16 BoF for Grid Developers and Deployers Leveraging Shibboleth GFD-I.079 Von Welch, NCSA Individual submission March 6, 2006 Report for the GGF 16 BoF for Grid Developers and Deployers Leveraging Shibboleth Copyright Open Grid Forum (2006). All Rights Reserved. Abstract

More information

THEBES: THE GRID MIDDLEWARE PROJECT Project Overview, Status Report and Roadmap

THEBES: THE GRID MIDDLEWARE PROJECT Project Overview, Status Report and Roadmap THEBES: THE GRID MIDDLEWARE PROJECT Project Overview, Status Report and Roadmap Arnie Miles Georgetown University adm35@georgetown.edu http://thebes.arc.georgetown.edu The Thebes middleware project was

More information

Service Delivery and Operations Report

Service Delivery and Operations Report 25-05-2017 Deliverable 5.2 Contractual Date: 30-04-2017 Actual Date: 25-05-2017 Grant Agreement No.: 731122 Work Package/Activity: 5/SA2 Task Item: Task 2 and Task 3 Nature of Deliverable: R Dissemination

More information

Enabling Grids for E-sciencE. EGEE security pitch. Olle Mulmo. EGEE Chief Security Architect KTH, Sweden. INFSO-RI

Enabling Grids for E-sciencE. EGEE security pitch. Olle Mulmo. EGEE Chief Security Architect KTH, Sweden.  INFSO-RI EGEE security pitch Olle Mulmo EGEE Chief Security Architect KTH, Sweden www.eu-egee.org Project PR www.eu-egee.org EGEE EGEE is the largest Grid infrastructure project in the World? : 70 leading institutions

More information

Introduction to Identity Management Systems

Introduction to Identity Management Systems Introduction to Identity Management Systems Ajay Daryanani Middleware Engineer, RedIRIS / Red.es Kopaonik, 13th March 2007 1 1 Outline 1. Reasons for IdM 2. IdM Roadmap 3. Definitions 4. Components and

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

DARIAH-AAI. DASISH AAI Meeting. Nijmegen, March 9th,

DARIAH-AAI. DASISH AAI Meeting. Nijmegen, March 9th, DARIAH-AAI DASISH AAI Meeting Nijmegen, March 9th, 2014 www.dariah.eu What is DARIAH? DARIAH: Digital Research Infrastructure for the Arts and Humanities One of the few ESFRI research infrastructures for

More information

AAI in EGI Current status

AAI in EGI Current status AAI in EGI Current status Peter Solagna EGI.eu Operations Manager www.egi.eu EGI-Engage is co-funded by the Horizon 2020 Framework Programme of the European Union under grant number 654142 User authentication

More information

Next-Generation Identity Federations. Andreas Åkre Solberg

Next-Generation Identity Federations. Andreas Åkre Solberg Next-Generation Identity Federations Andreas Åkre Solberg Identity Federations GÉANT3 JRA3 Task 2 Solving current challenges, and exploring next generation Identity Management Systems. 3 Research Activity

More information

3 rd TF-Netcast Meeting 14 May 2003 via H.323 video conference

3 rd TF-Netcast Meeting 14 May 2003 via H.323 video conference 3 rd TF-Netcast Meeting 14 May 2003 via H.323 video conference Issue 1, 16 May 2003 Author: Baiba Kaskina, Dan Mønster Participants: Alessandro Falaschi University of Roma Franca Fiumana CINECA Ernst Heiri

More information

GÉANT Mission and Services

GÉANT Mission and Services GÉANT Mission and Services Vincenzo Capone Senior Technical Business Development Officer CREMLIN WP2 Workshop on Big Data Management 15 February 2017, Moscow GÉANT - Networks Manages research & education

More information

Request for Comments: ISSN: S. Cantor Shibboleth Consortium August 2018

Request for Comments: ISSN: S. Cantor Shibboleth Consortium August 2018 Independent Submission Request for Comments: 8409 Category: Informational ISSN: 2070-1721 I. Young, Ed. Independent L. Johansson SUNET S. Cantor Shibboleth Consortium August 2018 Abstract The Entity Category

More information

Leveraging the InCommon Federation to access the NSF TeraGrid

Leveraging the InCommon Federation to access the NSF TeraGrid Leveraging the InCommon Federation to access the NSF TeraGrid Jim Basney Senior Research Scientist National Center for Supercomputing Applications University of Illinois at Urbana-Champaign jbasney@ncsa.uiuc.edu

More information

Scalable Negotiator for a Community Trust Framework in Federated Infrastructures (Snctfi)

Scalable Negotiator for a Community Trust Framework in Federated Infrastructures (Snctfi) Scalable Negotiator for a Community Trust Framework in Federated Infrastructures (Snctfi) Licia Florio (GÉANT), David Groep (Nikhef), Christos Kanellopoulos (GÉANT), David Kelsey (STFC), Mikael Linden

More information

Federated Access to Multimedia Content

Federated Access to Multimedia Content Federated Access to Multimedia Content Ajay Daryanani Middleware Engineer RedIRIS Zurich, 30th January 2009 1st Media Management and Distribution Workshop 1 Outline 1. Federated access to content Requirements

More information

International Grid Trust Federation

International Grid Trust Federation International Grid Trust Federation towards worldwide interoperability in identity management UK Presidency 2005 e-irg Meeting David L. Groep, IGTF and EUGridPMA Chair, 2005-12-13 Outline Grid Security

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in InCommon Federation ( Federation ) enables the participant to use Shibboleth identity attribute sharing technologies to manage access

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

Canadian Access Federation: Trust Assertion Document (TAD)

Canadian Access Federation: Trust Assertion Document (TAD) Submit Form Participant Name: Canadian Access Federation: Trust Assertion Document (TAD) 1. Purpose A fundamental requirement of Participants in the Canadian Access Federation is that they assert authoritative

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in InCommon Federation ( Federation ) enables the participant to use Shibboleth identity attribute sharing technologies to manage access

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

ORCID UPDATE. JISC Workshop, 16 June 2017

ORCID UPDATE. JISC Workshop, 16 June 2017 ORCID UPDATE JISC Workshop, 16 June 2017 Imagine a world where: You could search the internet and find all of a researcher s work with a single query in any browser You could auto-populate standard publication

More information

InCommon Policies and Practices

InCommon Policies and Practices InCommon Policies and Practices The documents listed below comprise the polices and practices under which the InCommon Federation and Participants operate. These documents should be reviewed prior to submitting

More information

Federated authentication for e-infrastructures

Federated authentication for e-infrastructures Federated authentication for e-infrastructures 5 September 2014 Federated Authentication for E-Infrastructures Jisc Published under the CC BY 4.0 licence creativecommons.org/licenses/by/4.0/ Contents Introduction

More information

The IRISGrid Infrastructure Seamless Support for VOs. JRES2005, Marseille

The IRISGrid Infrastructure Seamless Support for VOs. JRES2005, Marseille The IRISGrid Infrastructure Seamless Support for VOs Virtual Organisations Why a support infrastructure s own and require resources Shared Collective Resource Resource Resource Resource Resource Resource

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014

Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 Security Incident Response Trust Framework for Federated Identity (Sir-T-Fi) David Kelsey (STFC-RAL) REFEDS, Indianapolis 26 Oct 2014 Outline Input FIM4R requirements TNC2014 BoF Romain Wartel Security

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

EGI Check-in service. Secure and user-friendly federated authentication and authorisation

EGI Check-in service. Secure and user-friendly federated authentication and authorisation EGI Check-in service Secure and user-friendly federated authentication and authorisation EGI Check-in Secure and user-friendly federated authentication and authorisation Check-in provides a reliable and

More information

Minutes of the 23rd TF-Mobility & Network Middleware Meeting

Minutes of the 23rd TF-Mobility & Network Middleware Meeting Page 1/8 TITLE / REFERENCE 23 rd TF-Mobility and Network Middleware - Wednesday, 16 February 2011 Lyon, France. The meeting was hosted by the University of Lyon and CRU. Table of Contents 1. Welcome and

More information

A Simplified Access to Grid Resources for Virtual Research Communities

A Simplified Access to Grid Resources for Virtual Research Communities Consorzio COMETA - Progetto PI2S2 UNIONE EUROPEA A Simplified Access to Grid Resources for Virtual Research Communities Roberto BARBERA (1-3), Marco FARGETTA (3,*) and Riccardo ROTONDO (2) (1) Department

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

Minutes of the 25th TF-Mobility & Network Middleware Meeting

Minutes of the 25th TF-Mobility & Network Middleware Meeting Page 1/7 TITLE / REFERENCE 25 th TF-Mobility and Network Middleware - Wednesday, 9 th November 2011 Bologna, Italy. The meeting was hosted by GARR. Table of Contents 1. Welcome and Apologies... 1 2. Approval

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in InCommon Federation ( Federation ) enables the participant to use Shibboleth identity attribute sharing technologies to manage access

More information

Collaborative Technologies and Enterprise Middleware:

Collaborative Technologies and Enterprise Middleware: Collaborative Technologies and Enterprise Middleware: A View of the Next Few Years A Day in the Life of Jean Blue Chair: OOPS! After the break, we will have Session 2D: Middleware Authentication (instead

More information

Canadian Access Federation: Trust Assertion Document (TAD)

Canadian Access Federation: Trust Assertion Document (TAD) Participant Name: Royal Society of Chemistry Canadian Access Federation: Trust Assertion Document (TAD) 1. Purpose A fundamental requirement of Participants in the Canadian Access Federation is that they

More information

Canadian Access Federation: Trust Assertion Document (TAD)

Canadian Access Federation: Trust Assertion Document (TAD) Participant Name Wilfrid Laurier University Canadian Access Federation: Trust Assertion Document (TAD) 1. Purpose A fundamental requirement of Participants in the Canadian Access Federation is that they

More information

Canadian Access Federation: Trust Assertion Document (TAD)

Canadian Access Federation: Trust Assertion Document (TAD) Purpose A fundamental requirement of Participants in the Canadian Access Federation is that they assert authoritative and accurate identity attributes to resources being accessed, and that Participants

More information

Can R&E federations trust Research Infrastructures? - The Snctfi Trust Framework

Can R&E federations trust Research Infrastructures? - The Snctfi Trust Framework Can R&E federations trust Research Infrastructures? - The Snctfi Trust Framework 1a, David Groep b, Licia Florio c, Christos Kanellopoulos c, Mikael Linden d, Ian Neilson a, Stefan Paetow e, Wolfgang Pempe

More information

The Future of Indoor Plumbing. Dr Ken Klingenstein Director, Internet2 Middleware and Security

The Future of Indoor Plumbing. Dr Ken Klingenstein Director, Internet2 Middleware and Security The Future of Indoor Plumbing Dr Ken Klingenstein Director, Internet2 Middleware and Security Topics The Work So far Indoor, policy-based plumbing IdM in the enterprise Inter-realm and inter-institutional

More information

This talk aims to introduce the Shibboleth web authentication/authorization framework and its intended deployment in the UK academic community and

This talk aims to introduce the Shibboleth web authentication/authorization framework and its intended deployment in the UK academic community and This talk aims to introduce the Shibboleth web authentication/authorization framework and its intended deployment in the UK academic community and the University. Shibboleth named after an event in the

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

Canadian Access Federation: Trust Assertion Document (TAD)

Canadian Access Federation: Trust Assertion Document (TAD) Participant Name:_Unversity of Regina Canadian Access Federation: Trust Assertion Document (TAD) 1. Purpose A fundamental requirement of Participants in the Canadian Access Federation is that they assert

More information

Identity management. Tuomas Aura CSE-C3400 Information security. Aalto University, autumn 2014

Identity management. Tuomas Aura CSE-C3400 Information security. Aalto University, autumn 2014 Identity management Tuomas Aura CSE-C3400 Information security Aalto University, autumn 2014 Outline 1. Single sign-on 2. SAML and Shibboleth 3. OpenId 4. OAuth 5. (Corporate IAM) 6. Strong identity 2

More information

InCommon Federation: Participant Operational Practices

InCommon Federation: Participant Operational Practices InCommon Federation: Participant Operational Practices Participation in the InCommon Federation ( Federation ) enables a federation participating organization ( Participant ) to use Shibboleth identity

More information

RCauth.eu / MasterPortal update

RCauth.eu / MasterPortal update RCauth.eu / MasterPortal update Mischa Sallé msalle@nikhef.nl 5 th AARC face-to-face meeting, Aθηνα 21 March 2017 Mischa Sallé (Nikhef) 1 / 11 Reminder of motivation Access to X.509 resources made easy

More information

SAML2 Metadata Exchange & Tagging

SAML2 Metadata Exchange & Tagging SAML2 Metadata Exchange & Tagging TNC 2009 Malaga, 10. June 2009 Thomas Lenggenhager thomas.lenggenhager@switch.ch Overview 1 What s the Problem? 2 Scalable Metadata Exchange 3 Metadata Tagging 4 Summary

More information

TCS SAML demo background

TCS SAML demo background TCS SAML demo background https://www.digicert.com/sso David Groep TCS PMA and Nikhef TCS TNC2015 Workshop June 16, 2015 SAML Issuance via the DigiCert SSO portal Graphic courtesy Jan Meijer, Uninett, 2009(!)

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in the InCommon Federation ( Federation ) enables a federation participating organization ("Participant") to use Shibboleth identity

More information

TERENA, the NRENs, GÉANT & promoting Campus Best Practice

TERENA, the NRENs, GÉANT & promoting Campus Best Practice Networkshop 42 Leeds, UK 2 April 2014 John Dyer dyer@terena.org www.terena.org TERENA, the NRENs, GÉANT & promoting Campus Best Practice About TERENA A not-for-profit association of NRENs. 1986 RARE:

More information

ArcGIS Server and Portal for ArcGIS An Introduction to Security

ArcGIS Server and Portal for ArcGIS An Introduction to Security ArcGIS Server and Portal for ArcGIS An Introduction to Security Jeff Smith & Derek Law July 21, 2015 Agenda Strongly Recommend: Knowledge of ArcGIS Server and Portal for ArcGIS Security in the context

More information

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES

INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES INCOMMON FEDERATION: PARTICIPANT OPERATIONAL PRACTICES Participation in InCommon Federation ( Federation ) enables the participant to use Shibboleth identity attribute sharing technologies to manage access

More information